PT-2001-1567 · Microsoft · Sql Server

Published

2001-07-21

·

Updated

2018-10-12

·

CVE-2001-0344

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft SQL Server versions 7.0 and 2000 Gold
Description A security issue in Microsoft SQL Server allows local database users to elevate their privileges. This is achieved by reusing a cached connection of the sa administrator account through an SQL query method in Mixed Mode.
Recommendations For Microsoft SQL Server version 7.0, consider restricting access to the sa administrator account to prevent privilege escalation. For Microsoft SQL Server 2000 Gold, restrict the use of Mixed Mode to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-0344

Affected Products

Sql Server